Threat modeling can help give organizations the extra insights needed to secure their on-premises and cloud environments. The Cloud Security Alliance notes the importance of assessing the controls that an organization already has in place, sizing up vulnerabilities particular to its industry and rating the threats. Threat modeling consists of identifying what each application in a system does, defining enterprise assets, profiling each application and specifying its security properties, detecting potential threats and then documenting adverse events and actions taken to mitigate them. Expert: “All organizations can and should do some level of threat modeling; it doesn’t have to be resource-intensive””]
Source: https://www.govinfosecurity.com/threat-modeling-making-right-moves-a-17368